Skip to content
Noroxi

yaws records

11 published records for vendor yaws.

All records

11 records
  • Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.

    HighCVSS 7.5Proof of conceptEPSS 81%

    yaws · yawsJul 7, 2017

  • CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

    CriticalCVSS 9.8No exploitEPSS 17%

    yaws · yawsSep 9, 2020

  • WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

    CriticalCVSS 9.8No exploitEPSS 3%

    yaws · yawsSep 9, 2020

  • CVE-2011-4350
    31Monitor

    Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.

    MediumCVSS 6.5WeaponizedEPSS 16%

    yaws · yawsNov 26, 2019

  • yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr

    MediumCVSS 6.1No exploitEPSS 1%

    yaws · yawsDec 10, 2019

  • CVE-2009-0751
    23Monitor

    Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he

    MediumCVSS 5.0Proof of conceptEPSS 10%

    yaws · yawsMar 2, 2009

  • CVE-2009-4495
    23Monitor

    Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit

    MediumCVSS 5.0Proof of conceptEPSS 9%

    yaws · yawsJan 13, 2010

  • CVE-2010-4181
    23Monitor

    Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc

    MediumCVSS 5.0Proof of conceptEPSS 8%

    yaws · yawsNov 4, 2010

  • yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin

    MediumCVSS 5.5No exploitEPSS 0%

    yaws · yawsMay 15, 2020

  • CVE-2005-2008
    20Monitor

    Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai

    MediumCVSS 5.0No exploitEPSS 1%

    yaws · webserverJun 17, 2005

  • CVE-2011-5025
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri

    MediumCVSS 4.3Proof of conceptEPSS 3%

    yaws · yawsDec 29, 2011